Avannubo Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Avannubo Listed by rhysida Ransomware Group (reported June 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 21 June 2023, the ransomware group known as rhysida listed Avannubo on its leak site, claiming to have exfiltrated internal files and made them publicly available. The number of people affected remains unknown, and independent confirmation of the full scope has not been published. For customers, employees, and partners of a firm that supplies IP telephony, mobile, and internet services, the practical concern is straightforward: internal business records, if exposed, can contain contact details, account information, contracts, and operational data that outsiders can misuse for fraud, phishing, or further intrusion.
Public detail is limited to the group’s own listing and the description of Avannubo as a licensed technology-services provider. What follows sets out only what has been reported, places the claim in the context of how rhysida typically operates, and outlines concrete steps for anyone who may be affected.
Inside the incident
According to the listing dated 21 June 2023, rhysida asserted that it had conducted a ransomware attack against Avannubo and exfiltrated internal files. The group’s post described a data catalog of 165 GB comprising 198 760 files and stated that the material had been uploaded to public access. No independent verification of those figures, of the exact date of intrusion, or of the technical method used has been included in the available record. The number of individuals whose information may appear in the files is listed as unknown. The only data-type description supplied is “internal files exfiltrated in a ransomware attack.” Beyond the group’s claim that the files were made fully available, further operational detail remains undisclosed.
Inside rhysida
Rhysida is a ransomware operation that emerged in public reporting in 2023. Like other groups in this category, it typically gains access to a victim network, steals data, encrypts systems, and then pressures the organisation by threatening to publish the stolen material on a dedicated leak site if a ransom is not paid. The group has been observed using double-extortion tactics—combining encryption with the threat of data release—and has listed a range of organisations across multiple sectors. Its leak-site posts commonly include volume claims, file counts, and taunting language aimed at both the victim and third-party “data hunters.”
In the Avannubo case, the listing follows that pattern: the group claims a completed exfiltration, supplies a size and file count, and asserts that the material has been placed in public reach. Those statements remain the group’s unverified claims; they have not been independently corroborated in the facts available for this incident. Rhysida’s broader activity is well documented in open-source reporting, but no additional victim-specific statements beyond the June 2023 listing are part of the record used here.
Who is Avannubo?
Avannubo is described as a global provider of technological services holding official licences for IP telephony, mobile phones, and internet access. Organisations of this type sit at the intersection of telecommunications and IT services: they manage customer accounts, network configurations, billing records, support tickets, and often employee and partner data. Because they handle connectivity and communications infrastructure, a compromise can affect not only the company’s own staff but also the end users and businesses that rely on those services.
A breach involving such a provider is consequential precisely because the data it holds is operationally sensitive. Even when the exact contents of a leak remain unconfirmed, the sector’s typical holdings—customer identifiers, service agreements, technical documentation, and internal correspondence—create avenues for social engineering, account takeover, and competitive or regulatory harm. Public reporting has not established negligence or specific security failures on Avannubo’s part; the incident is known only through the ransomware group’s listing.
What was likely exposed
The facts name the exposed material only as internal files exfiltrated in a ransomware attack. The rhysida listing further claims a volume of 165 GB and 198 760 files, stated to have been uploaded in full to public access. No itemised inventory of data types—such as names, email addresses, financial records, or credentials—has been supplied in the available record. Exact contents are therefore unconfirmed.
Organisations that supply IP telephony, mobile, and internet services commonly maintain customer account data, contact details, billing and contract files, network and configuration documentation, employee records, and internal correspondence. Whether any or all of those categories appear in the claimed archive cannot be stated as fact from the information given. Readers should treat the group’s volume and file-count figures as claims until corroborated by independent sources.
What's at stake
For individuals whose information may be inside the files, the immediate risks are practical rather than abstract. Exposed contact details and account identifiers can be used to craft convincing phishing messages or to attempt account takeover at other services. Internal documents can reveal business relationships, project details, or technical information that aid further targeting. Because the number of people affected is unknown, anyone who has been a customer, employee, or partner of Avannubo has reason to remain alert without assuming they are definitively included.
For the organisation itself, public release of internal files can damage trust, trigger regulatory scrutiny, and create ongoing operational costs related to incident response, customer notification, and system hardening. The ransomware group’s decision to claim full public upload increases the chance that copies will circulate among opportunistic actors even if the original listing is later removed. None of these outcomes has been quantified in the public facts; they are the ordinary consequences that follow when internal corporate data is alleged to have been stolen and posted.
If your data was in this claimed breach
If you have a past or present relationship with Avannubo, treat the listing as a prompt to tighten basic hygiene rather than as proof that your personal data is confirmed exposed. Practical first steps include:
- Change passwords on any accounts tied to the same email address you used with Avannubo, and enable multi-factor authentication where available.
- Watch for unexpected password-reset messages, invoices, or support requests that reference the company or its services; verify them through official channels before responding.
- Review bank and credit-card statements for unfamiliar charges if you ever paid Avannubo electronically.
- Be cautious of unsolicited calls or messages that claim to be from the company or from “data recovery” services.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach datasets; that check will not confirm or deny presence in this specific incident, but it can surface other exposures that warrant the same precautions.
Public detail on this incident remains limited to the rhysida claim of 21 June 2023. Continue to rely on official statements from Avannubo or competent authorities for any later confirmation of scope or notification obligations. Until then, measured vigilance is the proportionate response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
KISS FM Listed by rhysida Ransomware GroupTshwane University of Technology Listed by rhysida Ransomware GroupAbdali Hospital Listed by rhysida Ransomware GroupKauno Technologijos Universitetas Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Avannubo Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.